How Agent Reach Extracts Cookies from Browsers: Implementation and Supported Platforms
Agent Reach extracts authentication tokens from Chrome, Firefox, Edge, Brave, and Opera using either the Rust-based rookiepy library or the pure-Python browser_cookie3 fallback, filters them against domain-specific platform specifications, and writes the results to ~/.agent_reach.yaml for automated social media channel configuration.
Agent Reach is an open-source automation framework that authenticates with social media platforms using cookies from your local browser sessions. Understanding how it extracts and processes these cookies is essential for troubleshooting authentication issues and extending support to new platforms.
The Dual-Backend Extraction Engine
The cookie extraction logic resides in agent_reach/cookie_extract.py and implements a priority-based backend selection strategy. The system prefers rookiepy—a Rust-based extractor known for faster performance and better reliability—falling back to browser_cookie3 only when necessary.
At runtime, the extract_all() function attempts to import the preferred library:
try:
import rookiepy # preferred backend
use_rookiepy = True
except ImportError:
import browser_cookie3 # fallback
use_rookiepy = False
This import pattern occurs inside extract_all() (lines 55-63), ensuring that missing dependencies do not crash the application. When rookiepy is available, the system uses browser-specific functions like rookiepy.chrome() or rookiepy.firefox(). Otherwise, it calls equivalent methods from browser_cookie3.
Platform-Specific Cookie Specifications
Agent Reach does not extract arbitrary cookies. Instead, it matches cookies against a static PLATFORM_SPECS list (defined at lines 15-41 in cookie_extract.py) that defines exactly which domains and cookie names are required for each service:
PLATFORM_SPECS = [
{"name": "Twitter/X", "domains": [".x.com", ".twitter.com"],
"cookies": ["auth_token", "ct0"], "config_key": "twitter"},
{"name": "XiaoHongShu", "domains": [".xiaohongshu.com"],
"cookies": None, "config_key": "xhs"},
{"name": "Bilibili", "domains": [".bilibili.com"],
"cookies": ["SESSDATA", "bili_jct"], "config_key": "bilibili"},
# ... additional platforms
]
Each specification contains:
- domains: List of domain suffixes to match against cookie domains
- cookies: Either a list of specific cookie names to extract, or
Noneto serialize all matching cookies as a header string - config_key: The key used when writing results to the configuration file
For Twitter/X, the system specifically hunts for auth_token and ct0 cookies. For XiaoHongShu, it captures the entire cookie jar as a formatted string because the platform requires multiple dynamic tokens.
From Browser Database to Configuration File
The extract_all(browser: str) function orchestrates the full extraction pipeline. It accepts browser names (chrome, firefox, edge, brave, or opera) and returns a dictionary keyed by platform configuration keys.
The extraction flow follows these steps:
- Select backend based on availability (lines 78-88)
- Query browser store using
rookiepy.chrome()orbrowser_cookie3.chrome()(lines 101-109) - Filter by domain - iterates through the raw cookie jar and keeps only cookies where
domainends with a specified pattern - Extract or serialize - either pulls specific named cookies or formats all cookies as
name=value; name2=value2strings (lines 118-148)
The resulting structure looks like:
{
"twitter": {"auth_token": "abc123...", "ct0": "xyz789..."},
"xhs": {"cookie_string": "sessionid=def456; ..."},
"bilibili": {"SESSDATA": "ghi789...", "bili_jct": "jkl012..."}
}
The configure_from_browser() function (lines 225-290) then writes these values into the central Config object (agent_reach/config.py), persisting them to ~/.agent_reach.yaml. It also performs legacy syncs to the xfetch session file and writes a credentials.env file for the optional bird CLI.
Programmatic and CLI Usage
You can trigger cookie extraction programmatically or via command line:
Python API:
from agent_reach.cookie_extract import extract_all, configure_from_browser
from agent_reach.config import Config
cfg = Config()
cookies = extract_all("chrome")
print(cookies) # Dictionary of platform tokens
results = configure_from_browser("chrome", cfg)
for platform, ok, msg in results:
print(f"{platform}: {'✅' if ok else '❌'} {msg}")
Command Line:
# Auto-import during installation (tries Chrome, then Firefox)
agent-reach install --channels=twitter,xiaohongshu
# Manual browser selection
agent-reach configure --from-browser chrome
The CLI implementation in agent_reach/cli.py (lines 71-88) attempts Chrome first, then falls back to Firefox if no cookies are found, displaying status messages like "✅ Twitter/X: auth_token + ct0".
Summary
- Agent Reach extracts cookies in
agent_reach/cookie_extract.pyusing a priority system that prefersrookiepyoverbrowser_cookie3. - Supported browsers include Chrome, Firefox, Edge, Brave, and Opera, selected by passing the browser name to
extract_all(). - The PLATFORM_SPECS dictionary defines exactly which cookies to extract for each social media platform, filtering by domain and specific cookie names.
- Extracted tokens are written to
~/.agent_reach.yamlviaconfigure_from_browser(), with additional syncs to legacy session files.
Frequently Asked Questions
Which browsers does Agent Reach support for cookie extraction?
Agent Reach supports Chrome, Firefox, Edge, Brave, and Opera. The extract_all() function in agent_reach/cookie_extract.py accepts these browser names as string arguments and maps them to the appropriate backend functions in either rookiepy or browser_cookie3.
What specific cookies does Agent Reach extract for Twitter/X?
For Twitter/X, Agent Reach specifically extracts auth_token and ct0 cookies from domains ending in .x.com or .twitter.com. These are defined in the PLATFORM_SPECS list at lines 15-41 of cookie_extract.py, where the cookies key lists the required authentication tokens.
How does Agent Reach handle cookie extraction when rookiepy is not installed?
If rookiepy is not available, Agent Reach automatically falls back to browser_cookie3, a pure-Python library. The code wraps the import in a try-except block (lines 55-63) and sets a boolean flag that determines which backend functions to call during the extraction phase.
Where does Agent Reach store extracted cookies after extraction?
Extracted cookies are persisted to ~/.agent_reach.yaml through the Config class in agent_reach/config.py. The configure_from_browser() function also creates ancillary files including a legacy xfetch session file and an optional credentials.env for the bird CLI tool.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →